IP Library Granted Patent US 10,740,135
Granted Patent B2
US 10,740,135 · App. 16/144,320 · Granted Aug 11, 2020

System and method for distributed security forensics

Inventors: Liron Levin (Herzliya, IL); Dima Stopel (Herzliya, IL); Ami Bizamcher (Kiryat Ono, IL); Michael Kletselman (Tel Aviv, IL); John Morello (Baton Rouge, LA)
Assignee: Twistlock, Ltd
G06F9/45558G06F9/44505G06F16/2379G06F21/51G06F21/53G06F21/54G06K9/6256G06N20/00H04L63/20G06F2009/45583G06F2009/45587G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,740,135
App. No.
16/144,320
Granted
Aug 11, 2020
Kind
B2
Abstract

A host device and method for efficient distributed security forensics. The method includes creating, at a first host device configured to run a first virtualization entity, a first event index for the first virtualization entity; encoding at least one event related to the first virtualization entity; updating the first event index based on the encoded at least one event; and sending the first event index to a master console, wherein the master console is configured to receive a plurality of event indices created by a plurality of host devices with respect to a plurality of virtualization entities.

Claims (39)

1. A method for efficient distributed security forensics, comprising:

creating, at a first host device configured to run a first virtualization entity, a first event index for the first virtualization entity, wherein the first event index is an append-only event index, wherein the first event index records changes to the first event index;

encoding at least one event related to the first virtualization entity;

updating the first event index based on the encoded at least one event; and

sending the first event index to a master console, wherein the master console is configured to receive a plurality of event indices created by a plurality of host devices with respect to a plurality of virtualization entities.

2. The method of claim 1 , wherein each event includes a process having a process path, wherein encoding the at least one event includes replacing at least a portion of each event with at least one code representing at least the process path of the respective process.

3. The method of claim 1 , wherein the first event index is optimized with respect to write time, wherein the first event index is not optimized with respect to read time.

4. The method of claim 1 , wherein the at least one event is encoded based on an event profile of the first virtualization entity, wherein the encoded at least one event is decoded by the master console based on the event profile of the first virtualization entity.

5. The method of claim 4 , wherein the event profile of the first virtualization entity defines the encoding process used for encoding the event.

6. The method of claim 4 , wherein the event profile of the first virtualization entity further includes the first event index.

7. The method of claim 1 , wherein the first virtualization entity is any of: a software container, a plurality of software containers, and a lightweight virtual machine.

8. The method of claim 1 , further comprising:

compressing the at least one event.

9. The method of claim 1 , wherein the at least one event includes at least one of: at least one networking event, and at least one filesystem access event.

10. The method of claim 1 , wherein the first virtualization entity is any of: at least one container, a virtual machine, an image, a host operating system service, a user, a file, and a network interface.

11. A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

creating, at a first host device configured to run a first virtualization entity, a first event index for the first virtualization entity, wherein the first event index is an append-only event index, wherein the first event index records changes to the first event index;

encoding at least one event related to the first virtualization entity;

updating the first event index based on the encoded at least one event; and

sending the first event index to a master console, wherein the master console is configured to receive a plurality of event indices from a plurality of host devices configured to run a plurality of virtualization entities.

12. A host device for efficient distributed security forensics, wherein the host device is configured to run a first virtualization entity, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

create a first event index for the first virtualization entity, wherein the first event index is an append-only event index, wherein the first event index records changes to the first event index;

encode at least one event related to the first virtualization entity;

update the first event index based on the encoded at least one event; and

send the first event index to a master console, wherein the master console is configured to receive a plurality of event indices created by a plurality of other host devices with respect to a plurality of virtualization entities.

13. The host device of claim 12 , wherein each event includes a process having a process path, wherein encoding the at least one event includes replacing at least a portion of each event with at least one code representing at least the process path of the respective process.

14. The host device of claim 12 , wherein the first event index is optimized with respect to write time, wherein the first event index is not optimized with respect to read time.

15. The host device of claim 12 , wherein the at least one event is encoded based on an event profile of the first virtualization entity, wherein the encoded at least one event is decoded by the master console based on the event profile of the first virtualization entity.

16. The host device of claim 15 , wherein the event profile of the first virtualization entity defines the encoding process used for encoding the event.

17. The host device of claim 15 , wherein the event profile of the first virtualization entity further includes the first event index.

18. The host device of claim 12 , wherein the first virtualization entity is any of:

a software container, a plurality of software containers, and a lightweight virtual machine.

19. The host device of claim 12 , wherein the host device is further configured to:

compress the at least one event.

20. The host device of claim 12 , wherein the at least one event includes at least one of: at least one networking event, and at least one filesystem access event.

21. The host device of claim 12 , wherein the first virtualization entity is any of:

at least one container, a virtual machine, an image, a host operating system service, a user, a file, and a network interface.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: TWISTLOCK LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 068685/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2018
From: LEVIN, LIRON; STOPEL, DIMA; BIZAMCHER, AMI; KLETSELMAN, MICHAEL; MORELLO, JOHN
To: TWISTLOCK, LTD.
Reel/Frame 046996/0675 →
Continuity (2)
Provisional Application 62700586 · Jul 19, 2018
Related Publication 20200026541A1 · Jan 23, 2020